SMB forced authentication vulnerability in versions prior to 2025.35.000 of Sage 200 Spain. This vulnerability allows an authenticated attacker with administrator privileges to obtain NTLMv2-SSP Hash by changing any of the paths to a UNC path pointing to a server controlled by the attacker.
History

Fri, 07 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Mar 2025 11:00:00 +0000

Type Values Removed Values Added
Description SMB forced authentication vulnerability in versions prior to 2025.35.000 of Sage 200 Spain. This vulnerability allows an authenticated attacker with administrator privileges to obtain NTLMv2-SSP Hash by changing any of the paths to a UNC path pointing to a server controlled by the attacker.
Title SMB forced authentication vulnerability in Sage 200 Spain
Weaknesses CWE-294
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2025-03-07T10:56:52.391Z

Updated: 2025-03-07T13:31:40.805Z

Reserved: 2025-03-03T13:11:18.262Z

Link: CVE-2025-1887

cve-icon Vulnrichment

Updated: 2025-03-07T13:30:14.425Z

cve-icon NVD

Status : Received

Published: 2025-03-07T11:15:16.040

Modified: 2025-03-07T11:15:16.040

Link: CVE-2025-1887

cve-icon Redhat

No data.